Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6826
HistoryJun 20, 2018 - 3:41 a.m.

Authorization Bypass

2018-06-2003:41:09
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

EPSS

0.001

Percentile

49.6%

angular-jwt is vulnerable to authorization bypasses. The library’s whitelist entries are treated as regular expressions meaning that the . separator will match any character. This allows a malicious user to set up a domain name to bypass the whitelist filter e.g. if the entry is example.entry.io, a malicious user can use setup a domain such as exampleXentry.io to bypass the filter.

EPSS

0.001

Percentile

49.6%

Related for VERACODE:6826